<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>MDA on Nicola Suter</title><link>https://nicolasuter.ch/tags/mda/</link><description>Recent content in MDA on Nicola Suter</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>© 2026 Nicola Suter</copyright><lastBuildDate>Wed, 29 Jul 2026 20:33:02 +0000</lastBuildDate><atom:link href="https://nicolasuter.ch/tags/mda/rss.xml" rel="self" type="application/rss+xml"/><item><title>Where are my CloudAppEvents?</title><link>https://nicolasuter.ch/til/cloudappevents/</link><pubDate>Wed, 29 Jul 2026 20:33:02 +0000</pubDate><guid>https://nicolasuter.ch/til/cloudappevents/</guid><description>&lt;p&gt;During a recent engagement I stumbled across an interesting observation: the Defender for Cloud Apps advanced hunting table &lt;code&gt;CloudAppEvents&lt;/code&gt; was empty, even though the tenant had adopted Microsoft 365 collaboration and security tooling.&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="auto"
 alt="Cloudappevents"
 width="1355"
 height="409"
 src="https://nicolasuter.ch/til/cloudappevents/cloudappevents-empty_hu_1655c38c8d214ace.png"
 srcset="https://nicolasuter.ch/til/cloudappevents/cloudappevents-empty_hu_1655c38c8d214ace.png 800w, https://nicolasuter.ch/til/cloudappevents/cloudappevents-empty_hu_96b3572183cacb6.png 1280w"
 sizes="(min-width: 768px) 50vw, 65vw"
 data-zoom-src="https://nicolasuter.ch/til/cloudappevents/cloudappevents-empty.png"&gt;&lt;figcaption&gt;No events in the CloudAppEvents table&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The Microsoft 365 app connector was reported as healthy, with the initial connection dating back to 2022:&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="auto"
 alt="App Connector"
 width="1465"
 height="398"
 src="https://nicolasuter.ch/til/cloudappevents/mda-appconnectors_hu_3fea45a8fffedb31.png"
 srcset="https://nicolasuter.ch/til/cloudappevents/mda-appconnectors_hu_3fea45a8fffedb31.png 800w, https://nicolasuter.ch/til/cloudappevents/mda-appconnectors_hu_3f9be7bd56a7a9ee.png 1280w"
 sizes="(min-width: 768px) 50vw, 65vw"
 data-zoom-src="https://nicolasuter.ch/til/cloudappevents/mda-appconnectors.png"&gt;&lt;figcaption&gt;Healthy App Connector&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;However, when opening the connector, none of the Microsoft 365 components were actually selected:&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="auto"
 alt="Users"
 width="2044"
 height="1078"
 src="https://nicolasuter.ch/til/cloudappevents/missing_hu_c4bdd4134ccfef2f.png"
 srcset="https://nicolasuter.ch/til/cloudappevents/missing_hu_c4bdd4134ccfef2f.png 800w, https://nicolasuter.ch/til/cloudappevents/missing_hu_6f7d38978425045d.png 1280w"
 sizes="(min-width: 768px) 50vw, 65vw"
 data-zoom-src="https://nicolasuter.ch/til/cloudappevents/missing.png"&gt;&lt;figcaption&gt;No components selected&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;So either someone forgot to tick the boxes back in 2022, or Microsoft used different auto-provisioning defaults at the time.&lt;/p&gt;
&lt;p&gt;This is also called out in the Microsoft docs &lt;cite&gt;&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/cite&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;In January 2026, the default values were added to support complete security coverage. If you configured your application before January 2026, make sure you select all of the default options and select Connect again to update your configuration.&lt;cite&gt;&lt;sup id="fnref1:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/cite&gt;&lt;/p&gt;
&lt;/blockquote&gt;&lt;blockquote&gt;&lt;p&gt;For maximum protection, we recommend selecting all Microsoft 365 components. Some threat detection and response functionalities don&amp;rsquo;t work unless all required components are properly selected.&lt;cite&gt;&lt;sup id="fnref2:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/cite&gt;&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;Interestingly, on another, more recently onboarded tenant where the connector had never been modified, all boxes were ticked except for file monitoring.&lt;/p&gt;</description></item></channel></rss>